Incidents
Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups
Leak-site victims · 7d
203
Leak-site victims · 30d
1K
Active groups · 30d
8011 new
Most active · 7d
the gentlemen
Breaches added · 30d
7
Accounts exposed · 30d
34.6MHIBP
Ransomware & extortion groups · activityleak-site posts · 90-day window · click a group for its profile
| # | Group | 7d | trend | 30d | 90d | all-time* | Last post | Status | Estimated earnings (public reporting) |
|---|---|---|---|---|---|---|---|---|---|
| 1 | the gentlemen | 30 | ▲8 | 152 | 400 | 400 | active | no public figure | |
| 2 | qilin | 29 | ▲16 | 113 | 364 | 364 | active | no public figure | |
| 3 | storm | 9 | ▼31 | 49 | 61 | 61 | active | no public figure | |
| 4 | krybit | 15 | ▲15 | 44 | 95 | 95 | active | no public figure | |
| 5 | akira | 10 | ▲3 | 43 | 87 | 87 | active | Approximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since. | |
| 6 | direwolf | 2 | ▼9 | 37 | 62 | 62 | active | no public figure | |
| 7 | coinbase cartel | 0 | = | 35 | 56 | 56 | active | no public figure | |
| 8 | inc ransom | 10 | ▲6 | 34 | 113 | 113 | active | no public figure | |
| 9 | lockbit5 | 5 | = | 27 | 54 | 54 | active | Over US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit… | |
| 10 | audit team | 10 | ▲1 | 24 | 26 | 26 | active | no public figure | |
| 11 | safepay | 9 | ▼2 | 22 | 67 | 67 | active | no public figure | |
| 12 | leakeddata | 1 | ▲1 | 20 | 39 | 39 | active | no public figure | |
| 13 | orova | 0 | = | 19 | 44 | 44 | active | no public figure | |
| 14 | emperador | 5 | = | 19 | 23 | 23 | active | no public figure | |
| 15 | zawoo | 0 | = | 19 | 19 | 19 | active | no public figure | |
| 16 | kazu | 0 | ▼17 | 17 | 17 | 17 | active | no public figure | |
| 17 | vexy | 4 | ▼3 | 16 | 16 | 16 | active | no public figure | |
| 18 | shinyhunters | 2 | = | 14 | 32 | 32 | active | no public figure | |
| 19 | panzer | 7 | ▲6 | 14 | 25 | 25 | active | no public figure | |
| 20 | black nevas | 1 | ▼12 | 14 | 14 | 14 | active | no public figure | |
| 21 | play | 3 | ▼1 | 13 | 47 | 47 | active | no public figure | |
| 22 | chaos | 3 | ▼1 | 13 | 35 | 35 | active | no public figure | |
| 23 | rhysida | 2 | ▼2 | 13 | 15 | 15 | active | no public figure | |
| 24 | pear | 0 | ▼1 | 12 | 23 | 23 | active | no public figure | |
| 25 | cyberleek | 0 | = | 12 | 12 | 12 | active | no public figure |
*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.
Incidents20 records · full details
| Victim | Group / type | Discovered | Details |
|---|---|---|---|
BN: higuchi-inc Report Error & Data Leak Warning tracker page ↗ | stormousfilter this group | · Jul 2, 2026 | www.higuchi-inc.co.jp/newsrelease/company/doc/unauthorized_access_incident.pdf // We have reviewed the report issued by HIGUCHI INC. To correct their mistake: the breach did not affect just one branch, but rather 3 different branches across various regions.Your data has not been leaked yet, as you are currently within an 8-day grace period. Before we publish any of your commercial or personal data, be aware that we possess 102 GB of Sage software backups, alongside numerous commercial documents.We await your reply to our messages. Follow the correct path to ensure nothing is leaked. We are waiting for you. |
Notice tracker page ↗ | stormousfilter this group | · Jul 2, 2026 | We will soon terminate our operations and services. All hosted data is scheduled for complete erasure within 60 days, before this blog goes offline permanently. |
maglificioliliana.com UPDATE-FULL DATA DUMP FREE PART1 tracker page ↗ | stormousfilter this group | · Jun 28, 2026 | Over +10GB GB of data has been accessed and exfiltrated. This includes product designs, historical fashion lines, and technical specifications for garments. Furthermore, we have obtained customer databases from various parts of the world, financial records, commercial contracts, employee data, personal files for all staff members within the network, daily operational documents, and more. |
lorenzoni-store.com UPDATE-FULL DATA DUMP FREE PART1 tracker page ↗ | stormousfilter this group | · Jun 28, 2026 | Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/ |
montechiaro-store.com UPDATE-FULL DATA DUMP FREE PART1 tracker page ↗ | stormousfilter this group | · Jun 28, 2026 | Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/ |
impulso-store.com UPDATE-FULL DATA DUMP FREE PART1 tracker page ↗ | stormousfilter this group | · Jun 28, 2026 | Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/ |
higuchi-inc.co.jp tracker page ↗ | stormousfilter this group | · Jun 28, 2026 | (Dallas - HongKong - LosAngeles ) Comprehensive financial statements including Balance Sheets, Asset records, Liabilities, Capital, Accounts Receivable (A/R), and Accounts Payable (A/P) database backups from Sage 50 (formerly Peachtree Accounting software), indicated by the .ptb file extension Corporate data detailing domestic and international inventory tracking, trade checking, and business operations. |
HIGUCHI USA, INC tracker page ↗ | stormousfilter this group | · Jun 28, 2026 | (Dallas - HongKong - LosAngeles ) Comprehensive financial statements including Balance Sheets, Asset records, Liabilities, Capital, Accounts Receivable (A/R), and Accounts Payable (A/P) database backups from Sage 50 (formerly Peachtree Accounting software), indicated by the .ptb file extension Corporate data detailing domestic and international inventory tracking, trade checking, and business operations. |
eogb.co.uk tracker page ↗ | stormousfilter this group | · Jun 28, 2026 | Deep access to Microsoft Dynamics GP containing complete corporate accounting, invoices, vendor details, and commercial transactions.Access to internal legal documents, partnership agreements, and customer contracts (such as CBIF OSMO agreements).Exfiltration of operational spreadsheets, financial reports, and executive documents via corporate |
eshacloudqa.com tracker page ↗ | stormousfilter this group | · Jun 28, 2026 | We have breached ESHA Research / ESHA Cloud Services and compromised their core product development databases. The exfiltrated data includes highly confidential industry secrets and formulation data Complete intellectual property containing secret product designs, manufacturing blueprints, and recipes (SupplementFormula, PureFood, FoodGroup).Deep laboratory data, nutritional testing breakdowns, and allergen classification records (SupplementIngredient, Analysis, AllergenGroup, Sensitive registries containing client profiles, user metrics, and market consumer data (Consumer, Activity). |
monoprix.tn tracker page ↗ | stormousfilter this group | · Jun 28, 2026 | Data description: Pending update |
Official Statement: Protecting palatineschool.org Infrastructure tracker page ↗ | stormousfilter this group | · Jun 28, 2026 | During our routine network security audits, our team discovered critical structural vulnerabilities within Palatine School, which granted us full, unrestricted access to their central server (PALDC2020). We had the technical capacity to access every directory, including pupil databases ( StudentData NHS NO ) , Pupil Admin - Users -FocusIT) and staff records Personnel.We want to announce that we have locked down this operation and decided to leak absolutely nothing.This is an institution dedicated to children and special needs education. Unlike corporate thieves or ruthless threat actors, we operate with a strict code of ethics: we do not target children, schools, or healthcare facilities.Instead of destroying them, we have chosen to act as an uninvited security audit. We are using our platform to publicly invite the administration of Palatine School to contact us privately. We will provide them with the full technical details of the critical vulnerabilities we discovered and guide them on how to patch their system for free, ensuring they are protected from other ruthless cyber criminals. |
Data Leak Update tracker page ↗ | stormousfilter this group | · Jun 26, 2026 | ** Do ML IT and vspsolutions.com.au think they are smarter than us? They are reporting the links where the data was uploaded, and they are being disabled. Therefore, and officially, we are preparing a private server on the Tor network to dump all the data of these companies and the data of others. Which will be available to everyone 24/7 along with a clear view of the extracted data, employees |
mlit.com.my UPDATE-FULL DATA DUMP NEW LINK 10GB tracker page ↗ | stormousfilter this group | · Jun 24, 2026 | FULL DATA DUMP . The compromised data includes highly sensitive internal operations and financial records. Among the leaked files are complete individual Campaign Profit and Loss (PnL) statements, detailed revenue sheets, clawbacks, and general ledger accounts for several linked entities, including Salesworks Pte Ltd Taiwan Branch and Shaves2u HK Limited. Additionally, we have extracted complete directory trees and file structures from the internal network shares and remote desktop sessions, revealing thousands of corporate folders such as JAG Group, SWGP Excel Import, and various financial databases. |
jaggroup.com UPDATE-FULL DATA DUMP NEW LINK tracker page ↗ | stormousfilter this group | · Jun 24, 2026 | Full database containing corporate emails (@jaggroup.com), Active Directory domain logins, and clear plain-text passwords.Complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration Multiple compressed archives (zBackups.zip, wetransfer packages), SQL server connection data, and IM.mdb database files.Internal project management sheets (Jag Project.xlsx), user listings, purchasing, and sales import logs. |
maglificioliliana.com tracker page ↗ | stormousfilter this group | · Jun 24, 2026 | Over 400 GB of data has been accessed and exfiltrated. This includes product designs, historical fashion lines, and technical specifications for garments. Furthermore, we have obtained customer databases from various parts of the world, financial records, commercial contracts, employee data, personal files for all staff members within the network, daily operational documents, and more. |
lorenzoni-store.com tracker page ↗ | stormousfilter this group | · Jun 24, 2026 | Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/ |
montechiaro-store.com tracker page ↗ | stormousfilter this group | · Jun 24, 2026 | Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/ |
impulso-store.com tracker page ↗ | stormousfilter this group | · Jun 24, 2026 | Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/ |
jaggroup.com UPDATE-FULL DATA DUMP tracker page ↗ | stormousfilter this group | · Jun 22, 2026 | Full database containing corporate emails (@jaggroup.com), Active Directory domain logins, and clear plain-text passwords.Complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration Multiple compressed archives (zBackups.zip, wetransfer packages), SQL server connection data, and IM.mdb database files.Internal project management sheets (Jag Project.xlsx), user listings, purchasing, and sales import logs. |
Breach & ransomware newsAll →
Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.